KITE 2025 New Product Award — Local IT | SACEEC
Risk and continuity

ISO 22301, measured against what the last test actually achieved

A recovery time objective written in a document is a target. ISO 22301 asks you to prove it, through a business impact analysis that justifies it and an exercise programme that tests it. Dimeri holds the analysis, the plan and the test result as one record.

What ISO 22301 requires

ISO 22301 specifies requirements for a business continuity management system. Like ISO 27001 it follows the common management system structure, clauses 4 to 10, and it is certifiable, so each shall is tested by an auditor. The 2019 revision simplified the wording and clarified the relationship between the business impact analysis and the risk assessment.

Clause 8.2 carries the analytical core. The business impact analysis identifies activities that support the delivery of products and services, assesses the impact over time of not performing them, and from that derives prioritised timeframes for resumption. Those timeframes are where recovery time objectives come from. A risk assessment then identifies what could disrupt those prioritised activities. The order matters: the impact analysis tells you what to protect, and the risk assessment tells you what to protect it from.

Clause 8.3 requires business continuity strategies and solutions chosen against those requirements, clause 8.4 requires plans and procedures with defined activation criteria and roles, and clause 8.5 requires an exercise programme. That last one is where certified organisations most often fall down: plans exist, exercises are scheduled, and the shortfalls the exercise exposed never become tracked actions.

The clauses Dimeri tracks

Dimeri holds the impact analysis, the dependencies, the plans and the exercise results as one connected record rather than four documents that age apart.

Clauses 4 and 5

Context, scope and leadership

The scope of the management system defined against the products and services it protects, with top management accountable for it.

  • Scope held with the activities and sites it covers
  • Interested parties and their continuity requirements
  • Business continuity policy with review dates
  • Roles, responsibilities and authorities assigned
Clause 8.2.2

Business impact analysis

Prioritised activities identified, the impact of their disruption assessed over time, and resumption timeframes derived from that impact rather than chosen.

  • Activities recorded with the products they support
  • Impact over time captured against agreed categories
  • Recovery time and point objectives derived and justified
  • Dependencies on people, systems, suppliers and sites
Clause 8.2.3

Risk assessment

The disruption risks to prioritised activities identified and assessed, using the same method as the wider risk register rather than a parallel one.

  • Disruption risks scored on the organisation's own criteria
  • Single points of failure surfaced across activities
  • Treatment actions with owners and due dates
  • Residual position reassessed after treatment
Clauses 8.3 and 8.4

Strategies, solutions and plans

Continuity strategies selected against the requirements the impact analysis set, with plans carrying activation criteria, roles and contacts.

  • Strategy recorded per prioritised activity
  • Plans held with owners and review cycles
  • Activation criteria and escalation defined
  • Contact and resource lists kept current
Clause 8.5

Exercise programme

Exercises that test the plans against their stated objectives, with results recorded and shortfalls acted on.

  • Exercise calendar with scope and type per test
  • Actual recovery measured against the objective
  • Shortfalls raised as owned actions, not observations
  • Post exercise reports drawn from the record
Clauses 9 and 10

Evaluation and improvement

Performance evaluation, internal audit, management review, and corrective action on nonconformities.

  • Internal audit programme covering the whole BCMS
  • Management review inputs gathered through the year
  • Nonconformities tracked with root cause to closure
  • Improvement actions on the system, not just the plans

How Dimeri covers ISO 22301

The gap in most continuity systems is between the plan and the evidence it works. Dimeri closes it by treating the exercise result as data rather than a report.

Objectives traceable to the analysis

Every recovery time objective links back to the impact assessment that produced it. When an auditor asks why four hours rather than twelve, the answer is the analysis rather than an opinion.

Exercises that produce actions

What the test achieved is recorded against what the plan promised, and every shortfall becomes an owned action with a date. That is the difference between an exercise programme and a filing exercise.

Dependencies mapped once

The systems, suppliers, sites and people each activity relies on are recorded once and reused by third party risk and operational risk, so the analysis earns its cost three times over.

Shared clauses with ISO 27001

Context, leadership, competence, documented information, internal audit and management review are common management system clauses. Organisations certified to both run one system with two scopes rather than two systems.

Getting ISO 22301 in place

  1. 1

    Scope against products and services

    The scope is defined by what the organisation must keep delivering, not by departments. Getting this wrong is the most common reason a first certification attempt stalls.

  2. 2

    Run the impact analysis first

    Prioritised activities and their impact over time come before any discussion of solutions. Recovery objectives fall out of that analysis rather than being set by whoever is loudest.

  3. 3

    Choose strategies and write plans

    Continuity solutions are selected against the requirements the analysis set, and plans carry activation criteria, roles and contacts, each with a named owner and a review cycle.

  4. 4

    Exercise, measure, improve

    The exercise programme tests plans against their objectives, shortfalls become tracked actions, and internal audit and management review keep the system running between certification visits.

ISO 22301 questions

What is the difference between the business impact analysis and the risk assessment?

The impact analysis asks what the organisation must resume and how quickly, by assessing the consequence over time of not performing each activity. The risk assessment then asks what could disrupt those prioritised activities. The analysis identifies what to protect; the assessment identifies what to protect it from. ISO 22301 requires both, in that order.

Do we need to be certified to use ISO 22301?

No. Many organisations align to the standard for the structure it provides without seeking certification, and its clauses work perfectly well as an internal discipline. Certification matters mainly when a client, regulator or insurer asks for independent assurance.

How often do plans need to be exercised?

The standard requires an exercise programme rather than a fixed frequency, leaving the organisation to justify a schedule proportionate to the activity's priority. Most set annual exercises for the highest priority activities with lighter walkthroughs in between. Dimeri enforces whichever cycle you set and shows when it slips.

How does this relate to the business continuity module?

This page describes the standard; the business continuity platform page covers the product in more depth, including the recovery objective tracking and dependency mapping. Both draw on the same underlying record.

Is this a substitute for the standard itself?

No. ISO 22301 is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to work to it.

Put ISO 22301 on one register

Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.